The Line of Death

Browser Security Bugs That Aren't: JavaScript in PDF

Forcing Edge to load a specific URL in a specific browser

New TLDs: Not Bad

Attack Techniques: Phishing via Local Files

New Recipes for 3rd Party Cookies

Captive Portals

“Batteries-Included” vs “Bloated”

Thoughts on Impact

The Line of Death (2017)

Practical Time Machines

“The entire 11 MB ZIP file was being read from disk a single byte at a time”

Demystifying Browsers

Microsoft's Three Browsers

Retiring Internet Explorer

Same-Site Cookies by Default

Spying on HTTPS

Surprise: Undead Session Cookies

Google Chrome–One Year In

Taking Off Your NameTag

Understanding the Limitations of HTTPS

Certified Malice

The Line of Death

Getting Started with Profile Guided Optimization

DLL Hijacking Just Won’t Die

My Next Adventure

The Collateral Damage from Apple's iOS Ad-Blocking API